4.9 • 696 Ratings
🗓️ 23 November 2016
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, November 23rd, 2016 edition of the Sands and it, Storms, |
0:06.3 | Stormcast. My name is Johannes Ulrich and the day I'm recording from Jacksonville, Florida. |
0:12.3 | If you're running WordPress, one thing you should and are probably aware of is that you need to |
0:18.4 | regularly update WordPress to make sure that you're patching |
0:23.0 | recently found vulnerabilities. Well it turns out in order to do so you need to connect to |
0:29.3 | one of WordPress's servers and download an update but as it turns out the only verification |
0:36.1 | of the update that's happening is an MD5 hash, |
0:39.2 | which of course at this point is not secure enough and could possibly be spoofed. |
0:46.5 | Now, these updates happen over SSL, so you still have the SSL layer here to protect yourself. |
0:53.5 | But as the author of this particular |
0:55.2 | advisory points out, WordPress still supports PHP 5.2.4, which doesn't support a lot of the |
1:03.7 | more modern advances to SSL. So you may also be out of luck there and opening yourself up to a man in the middle condition |
1:12.0 | that would allow someone to spoof the update server. The fix, well, there isn't really a fix |
1:18.9 | that you could apply easily. At least you should update to the latest version of PHP. So you do |
1:25.0 | have full access to everything that SZL has to offer. |
1:30.3 | Of course, this really has to be fixed on the WordPress side. |
1:34.1 | They need to use something else than an MD5 hash in order to check the integrity of the download. |
1:40.6 | At this point, I would say an MD5 hash is good enough to check for an accidental |
1:45.5 | corruption of the download, but not really good enough as a cryptographic verification. In order |
1:53.2 | to do that, you also need a secret, so you probably want, as the advisory suggests, use a private |
2:00.4 | public key algorithm in order to properly verify |
2:04.6 | these downloads. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.